CyLab faculty, students to present 10 papers at the 35th USENIX Security Symposium

Michael Cunningham

Aug 6, 2026

USENIX logo

Carnegie Mellon faculty and students will present on a wide range of topics at the 35th USENIX Security Symposium. Held in Baltimore on August 12-14, the event brings together experts from around the world, who will highlight the latest advances in the security and privacy of computer systems and networks.

Here, we’ve compiled a list of the 10 papers co-authored by CyLab Security and Privacy Institute members that are being presented at the event.

Stayin' Alive: How Global Stolen Data Markets Thrive on Telegram

Authors: Tina Marjanov, University of Cambridge; Taro Tsuchiya, Carnegie Mellon University; Konstantinos Ioannidis and Jack Hughes, University of Cambridge; Nicolas Christin, Carnegie Mellon University; Alice Hutchings, University of Cambridge

Abstract: Stolen data acts as a catalyst for many cybercriminal activities, such as spam campaigns, spear phishing, and identity theft. Studying online communities that serve stolen data helps combat those criminal activities. While anonymous marketplaces and forums have traditionally been the primary venue for stolen data, the chat-based messaging application Telegram has emerged as a popular alternative. Given Telegram's increased accessibility to the general public, it remains unclear how stolen data communities adapt their operations to this platform, circumvent moderation efforts, and create resilient communities. In this work, we characterize: i) where stolen data communities appear within Telegram's ecosystem, ii) what types of stolen data they offer, iii) where they operate from, and iv) how they evade detection. This paper offers four main contributions. First, we provide one of the largest longitudinal datasets of Telegram stolen data channels. Over one year, we manually curate 1,521 channels and collect 14 million messages and 3.6 million shared files. We show that the stolen data communities are largely disjoint from other communities on Telegram. Second, we categorize the types of stolen data with the aim of understanding the potential cybercrime they enable. Third, while existing literature focuses on English-speaking communities, we find that many channels operate in non-English languages and source stolen data from non-English markets. Fourth, those communities deploy various techniques to evade regulation. Notably, "gateway channels" that provide links to other stolen data channels play a crucial role in increasing longevity and growth rate. We conclude by providing implications not only for academic researchers but also for Telegram and law enforcement agencies across different jurisdictions seeking to monitor and moderate those activities.

Bridging Usability and Performance: A Tensor Compiler for Autovectorizing Homomorphic Encryption

Authors: Edward Chen, Fraser Brown, and Wenting Zheng, Carnegie Mellon University

Abstract: Homomorphic encryption (HE) offers strong privacy guarantees by enabling computation over encrypted data. However, the performance of tensor operations in HE is highly sensitive to how the plaintext data is packed into ciphertexts. Large tensor programs introduce numerous possible layout assignments, making it both challenging and tedious for users to manually write efficient HE programs.

In this paper, we present Rotom, a compilation framework that autovectorizes tensor programs into optimized HE programs. Rotom systematically explores a wide range of layout assignments, applies state-of-the-art optimizations, and automatically generates an equivalent, efficient HE program. At its core, Rotom utilizes a novel, lightweight ApplyRoll layout conversion operator to easily modify the underlying data layouts and unlock new avenues for performance gains. Our evaluation demonstrates Rotom scalably compiles all tensor workloads in under 5 minutes, reduces rotations in hand-tuned protocols by up to 3×, and achieves up to 80× performance improvement over prior autovectorization systems.

Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore

Authors: Kelechi G. Kalu, Sofia Okorafor, and Tanmay Singla, Purdue University; Sophie Chen, Carnegie Mellon University; Santiago Torres-Arias and James C. Davis, Purdue University

Abstract: Software signing is the most robust method for ensuring the integrity and authenticity of components in a software supply chain. Traditional signing tools burdened practitioners with key management and signer identification, creating both usability challenges and security risks. A new class of next-generation signing tools has automated many of these concerns, but little is known about their usability and its effect on adoption and effectiveness in practice. A usability evaluation can clarify the extent to which next-generation designs succeed and highlight priorities for improvement.

To fill this gap, we conducted the first usability study of Sigstore, a pioneering and widely adopted exemplar of next-generation signing. Through interviews with 17 industry experts, we examined (1) the problems and advantages associated with practitioners' tooling choices, (2) how and why their signing-tool usage has evolved over time, and (3) the contexts that cause usability concerns. Our findings illuminate the usability factors of next-generation signing tools and yield recommendations for toolmakers, adopting organizations, and the research community. Notably, components of next-generation tooling exhibit different levels of maturity and readiness for adoption, and integration flexibility is a common pain point, but potentially mitigable through plugins and APIs. Our results will help next-generation signing toolmakers further strengthen software supply chain security.

Distributed Synthesis of Differentially Private Tabular Datasets

Authors: Yucheng Fu, University of Virginia; Tianyao Gu and Elaine Shi, Carnegie Mellon University; Tianhao Wang, University of Virginia

Abstract: Differentially private synthetic data generation has emerged as a powerful tool for sharing data while protecting individuals' privacy. However, when the attributes of sensitive data are distributed across multiple entities such as hospitals, companies, or government agencies, accurately generating synthetic data becomes challenging. In particular, it is difficult to capture informative statistical correlations and use them to guide data synthesis without gathering the entire private dataset. In response to this challenge, we propose a secure multi-party computation protocol for differentially private tabular data synthesis in the distributed setting. Our protocol contains two new primitives. The first is a protocol that exploits distributed point functions to efficiently estimate two-way marginals (pairwise joint distributions of attributes) across vertically distributed data. The second is a protocol for generating noise via batched lookups in the cumulative distribution function table. As a concrete demonstration, we build a distributed version of AIM, a state-of-the-art DP data-synthesis algorithm. Our implementation achieves the same utility as its centralized version while reducing end-to-end runtime by orders of magnitude compared with prior work. For example, we can synthesize the "Adult" dataset in 24 minutes in a real-world WAN setting, whereas the existing protocol is estimated to take 57 days.

Chameleon Channels: Measuring YouTube Accounts Repurposed for Deception and Profit

Authors: Alejandro Cuevas, Carnegie Mellon University; Manoel Horta Ribeiro, Princeton University; Nicolas Christin, Carnegie Mellon University

Abstract: Online content creators spend significant time and effort building their user base through a long, often arduous process that requires finding the right "niche" to cater to. So, what incentive is there for an established content creator known for cat memes to completely reinvent their page channel and start promoting cryptocurrency services or covering electoral news events? And, if they do, do their existing subscribers not notice?

We explore this problem of repurposed channels, whereby a channel changes its identity and contents. We first characterize a market for "second-hand" social media accounts, which recorded sales exceeding USD 1M during our 6-month observation period. Observing YouTube channels (re)sold over these 6 months, we find that a substantial number (53%) are used to disseminate policy-sensitive content, often without facing any penalty. Even more surprisingly, these channels seem to gain rather than lose subscribers.

We estimate the prevalence of channel repurposing "in the wild," using two snapshots of 1.4M YouTube accounts sampled from an ecologically valid proxy. In a 3-month period, we estimate that  0.25% channels were repurposed. Through a set of experiments, we confirm that these repurposed channels share several characteristics with sold channels—mainly the fact that they have a significantly high presence of policy-sensitive content. Across repurposed channels, we find channels similar to those used in influence operations, as well as channels used for financial scams. Repurposed channels have large audiences; across two observed samples, repurposed channels collectively held 193M and 44M subscribers. We reason that purchasing an existing audience and the credibility associated with an established account is advantageous to financially- and ideologically motivated adversaries. This phenomenon is not exclusive to YouTube and we posit that the market for cultivating organic audiences is set to grow, particularly if it remains unchallenged by mitigations, technical or otherwise..

HasteBoots: Proving TFHE Programmable Bootstrapping in Seconds

Authors: Fengrun Liu, Carnegie Mellon University; Haofei Liang, Shanghai Jiao Tong University; Xiang Xie, East China Normal University and Primus Labs; Yu Yu, Shanghai Jiao Tong University; Wenting Zheng, Carnegie Mellon University; Yuncong Hu, Shanghai Jiao Tong University

Abstract: Fully Homomorphic Encryption (FHE) enables computations on encrypted data, ensuring privacy for outsourced computation. However, verifying the integrity of FHE computations remains a significant challenge, especially for bootstrapping, the most computationally intensive operation in FHE. Prior approaches, including zkVM-based solutions and general-purpose SNARKs, suffer from inefficiencies, with proof generation time ranging from several hours to days.

In this work, we propose HasteBoots, a succinct argument tailored for TFHE with programmable bootstrapping. By designing efficient protocols for arithmetic operations over quotient rings, HasteBoots achieves proof generation in a few seconds for TFHE evaluation with programmable bootstrapping, significantly outperforming the state-of-the-art, Zama (CCS'25). Moreover, HasteBoots supports batching multiple TFHE evaluations and bootstrappings, a feature that prior work cannot practically support due to prohibitive proving cost. HasteBoots can prove a batch of 16 operations within one minute, while maintaining succinct verification, requiring only 126 ms and a proof size of 0.28 MB. Our approach demonstrates the potential for scalable and efficient verifiable FHE, paving the way for practical, privacy-preserving computations.

Orbit: Optimizing Rescale and Bootstrap Placement with Integer Linear Programming Techniques for Secure Inference

Authors: Zikai Zhou, Tsinghua University; William Seo and Edward Chen, Carnegie Mellon University; Alex Ozdemir, Max Planck Institute for Security and Privacy; Fraser Brown and Wenting Zheng, Carnegie Mellon University

Abstract: Fully Homomorphic Encryption (FHE) allows computation on encrypted data without decrypting it. In theory, FHE makes privacy-preserving machine learning possible. In practice, however, it remains impractically slow for real workloads. A major source of slowdown is bootstrap operations; in CKKS, a popular FHE scheme for tensor workloads, the slowdown is compounded by scale management and rescale operations.

FHE compilers for machine learning inference aim to make bootstrap placement and scale management efficient and easy by compiling high-level tensor programs into optimized CKKS computations. Unfortunately, existing approaches miss crucial optimization opportunities because they overlook a key property of CKKS programs: bootstrap and rescale placement are fundamentally coupled through the level budget. In this paper, we present Orbit, an FHE compiler that jointly optimizes bootstrap and rescale placement through a novel Integer Linear Programming (ILP) formulation that reasons about both ciphertext level and scale constraints. To make this formulation tractable for structured tensor workloads, particularly convolutional neural networks, we introduce three techniques that reduce ILP complexity while preserving optimality. Across five workloads and multiple cryptographic parameter configurations, Orbit achieves a geometric mean speedup of 19% over DaCapo, 73% over Orion, and 52% over ReSBM, keeps compilation under 6 minutes, and retains model accuracy within 0.3% of plaintext execution.

Security and Privacy Considerations for Confirming Payments in Rwandan Mobile Money Systems

Authors: Oluwole A. Adewusi, Assane Gueye, Wallace S. Msagusa, Jema David Ndibwile, David Nkundineza, Okemawo Obadofin, and Wilson Rutaremara, Carnegie Mellon University Africa; Blase Ur, University of Chicago

Abstract: Mobile money (MoMo) services let users pay individual merchants or businesses using either a smartphone or a basic phone. They are widely used for commerce in African countries, including Rwanda. To better understand the security and privacy aspects of how Rwandan businesses confirm MoMo payments in practice, we interviewed 30 Rwandan business owners and employees. While MoMo services send payment confirmations over SMS to both senders (customers) and recipients (merchants), we found that merchants often inspect confirmation messages on customers' phones, not their own. The reasons included confirmation messages being sent only to business owners' (not employees') phones, busy markets, phones being physically unavailable, and delayed SMS delivery. Trust also played a major role. As the customer controls their phone, this workaround can enable fraud via screenshots of past messages or spoofed confirmations. As these confirmation messages include customers' account balances, participants also reported privacy concerns. In response, we investigated the design space of alternative workflows, finding promise in redesigning customers' confirmation screens to remove private information and to add a secret known only to the merchant. We reflect on designing for security and privacy under the unique constraints of Sub-Saharan Africa.

What Adults Will (and Won't) Do to Prove Their Age: Empirical Evidence from a Deceptive Web Experiment

Authors: Yanzi Lin and Cheng Zhang, Carnegie Mellon University; Madelyne Xiao, Princeton University; Lorrie Faith Cranor and Sarah Scheffler, Carnegie Mellon University

Abstract: As age verification laws proliferate across the United States and internationally, limited empirical evidence exists on how adults actually respond to these systems in practice. We conducted an IRB-approved, deceptive web experiment (n = 1,635) to examine how different age verification methods affect adults' decisions to access age-restricted content. Participants, recruited to evaluate R-rated movie clips, were randomly assigned to one of seven verification conditions: checkbox self-attestation, government-issued ID upload (with varying privacy reassurances), government-issued ID with liveness check, AI facial age estimation, or email age estimation. Completion rates varied substantially by method. Checkbox self-attestation achieved 99% completion, government-ID methods 18–27% regardless of reassurances, email 86%, and AI 51%. Follow-up surveys (n = 881) revealed low comfort even among participants who completed verification. Participants perceived government-ID and AI methods as significantly riskier, rated no method as particularly effective at preventing minors' access, and found government-ID methods significantly less convenient. Higher comfort and lower perceived risk were associated with higher completion. These findings have important implications for balancing child protection with adults' access rights. We offer recommendations for policymakers and platform operators implementing age verification systems.

Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification

Authors: Carter Luck, University of Massachusetts Amherst; Olive Franzese-McLaughlin, Vector Institute and University of Toronto; Elisaweta Masserova, Carnegie Mellon University; Akira Takahashi and Antigoni Polychroniadou, J.P. Morgan AI Research and AlgoCRYPT CoE; Nicolas Papernot, Vector Institute and University of Toronto

Abstract: Privacy-preserving machine learning auditing protocols allow auditors to assess models for properties such as accuracy or fairness, without revealing their internals or training data. This makes them especially attractive for auditing models deployed in sensitive domains such as healthcare or finance. For these protocols to be meaningful in real-world audit settings, though, their guarantees must reflect how the model will behave once deployed, rather than merely certifying its behavior during an audit. Existing security definitions often miss this mark: most certify model behavior only on a fixed audit dataset, without ensuring that the same guarantees generalize to other datasets drawn from the same distribution. We show that a model provider can attack many cryptographic model certification (CMC) schemes built on secure zero knowledge proofs (ZKP) by carefully engineering training data, resulting in models that exhibit benign behavior during an audit, but pathological behavior in practice. For example, we empirically demonstrate that an attacker can certify that a model achieves over 99% accuracy on an audit dataset, but less than 30% accuracy on fresh samples from the same distribution.

To address this gap, we formalize rigorous cryptographic security notions tailored to CMC frameworks, introduce a generic protocol template, and prove that it satisfies these requirements. Our results thus offer both cautionary evidence about existing approaches and constructive guidance for designing secure, privacy-preserving ML auditing protocols.